hylyt.co - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned hylyt.co and returned a suspicious verdict (score 32), categorised as credential-harvest. The page resolved to 91.108.99.220 on IPFFM Internet Provider Frankfurt GmbH in AU. 19 domains and 1 IP were contacted, over 38 HTTP requests. 16 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 32) · Confidence 35%
- Scanned URL:
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/12c12b42b1c7cb291269d0b6bee22bf6/34617592495.pdf - Domain: hylyt.co · IP: 91.108.99.220 · AS47583 · AU
- Server: hcdn
- Page title: Page not found - HyLyt
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 38
- Scan tier: fast · observed 2026-08-22 03:01:42 UTC
Malware communicating with this URL (16)
These samples were observed contacting or being served from hylyt.co. Each links to its full analysis.
- Phishing - referenced ·
09eed28d791f2ca1031d8b535d346707· first seen 2026-08-22 - Phishing - referenced ·
a3e56d6d66913bc1d01b5c13a81853eb· first seen 2026-08-21 - Phishing - referenced ·
a9efedc28b82c86398df4649f3fcca92· first seen 2026-08-16 - Phishing - referenced ·
8a85880b09b2e4c3dcfa008e00cc250f· first seen 2026-08-16 - Phishing - referenced ·
b7e06925a48d968bed432f4a906a6247· first seen 2026-08-16 - Phishing - referenced ·
222e2d132ab7cc54a1c7a9004bfe12ec· first seen 2026-08-16 - Phishing - referenced ·
afa722b13594d0e3a43bd1cf06141d6d· first seen 2026-08-16 - 94933939719.pdf - referenced ·
ce69242f6be9208d7ecefb1e5af44959· first seen 2026-08-15 - Phishing - referenced ·
8ddfb2e32ba49519e746bea18646d7b0· first seen 2026-08-15 - Phishing - referenced ·
dad01992f94c69a8b4e5a641d6a1b116· first seen 2026-08-15 - Phishing - referenced ·
79c1e6931b53220047598956155b7b39· first seen 2026-08-15 - Phishing - referenced ·
2aace0b77e4826d934408791b0cf9213· first seen 2026-08-15 - Phishing - referenced ·
46483ec7253a508ff55fa1f7f68e4213· first seen 2026-08-14 - Phishing - referenced ·
df433e9a602669d758c5a26dde519aa5· first seen 2026-08-13 - Phishing - referenced ·
5de9dfafeb391e59ce5655eda543fd11· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 91.108.99.220 - AS47583 IPFFM Internet Provider Frankfurt GmbH (Australia)
Observed indicators
- hylyt.co
- gmpg.org
- www.facebook.com
- js.hs-scripts.com
- fonts.googleapis.com
- www.googletagmanager.com
- www.clarity.ms
- web.sociorac.com
- forms.gle
- app.mailerlite.com
- track.mailerlite.com
- static.mailerlite.com
- maxcdn.bootstrapcdn.com
- api.whatsapp.com
- in.linkedin.com
- www.instagram.com
- twitter.com
- www.youtube.com
- code.tidio.co
- 91.108.99.220
Other scans of hylyt.co (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 15 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/cde235f29935d72674f46226ad6bab21/7 - 15 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/fcdd85e908f71ae651fb32be2f15da6b/7 - 14 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/ee08b4e24f8f479ac83a02ae9b8f6e80/7 - 13 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/676c8f0dbc7fd88b0df1984d44948772/x - 13 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/17c0de90c6bf776526da3deba0690fb4/w
Questions about hylyt.co
- Is hylyt.co safe?
- No. MalwareAnalyzer scanned hylyt.co on 22 Aug 2026 and returned a suspicious verdict with a score of 32 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with hylyt.co?
- 16 analysed samples communicate with this URL, including Phishing.
- How was hylyt.co checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of hylyt.co
Scanned on MalwareAnalyzer by Cyble · Open interactive scan